XenForo SQL Injection Warnings

B

Bonsai Coder

Guest
Some of my users report that when posting a long response (or taking a long time to type a response) they will sometimes get locked out of the site for an hour... after which they are allowed to return and everything runs as normal.

Looking into my server, I have ModSecurity enabled, and see a lot of "Rule 300016: Generic SQL injection protection" hits.

Here is an example:
Request: POST /threads/satsuki-repot.45070/draft

Action Description: Access denied with...
Click to expand...

Read more

Continue reading...